LoadLibrary failed for C:\WINDOWS\system32\jyrpvtbg.dll
C:\WINDOWS\system32\jyrpvtbg.dll NOT unregistered.
C:\WINDOWS\system32\jyrpvtbg.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\urqrstr.dll
C:\WINDOWS\system32\urqrstr.dll NOT unregistered.
re, bonsoir
voila le rapport de "OTMoveIt" et le résultat du scan avec "BitDefender :
-------------------------------------------------------------------------
C:\WINDOWS\system32\urqrstr.dll moved successfully.
C:\WINDOWS\system32\fccbyay.dll.vir moved successfully.
Created on 11.27.2007 17:44:37
BitDefender Online Scanner
Rapport d'analyse généré à: Tue, Nov 27, 2007 - 19:44:25
Voie d'analyse: A:\;C:\;D:\;E:\;
Statistiques
Temps
01:40:28
Fichiers
341636
Directoires
6905
Secteurs de boot
3
Archives
10200
Paquets programmes
11349
Résultats
Virus identifiés
18
Fichiers infectés
34
Fichiers suspects
0
Avertissements
0
Désinfectés
0
Fichiers effacés
46
Info sur les moteurs
Définition virus
879148
Version des moteurs
AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)
Analyse des plugins
14
Archive des plugins
38
Unpack des plugins
7
E-mail plugins
6
Système plugins
1
Paramètres d'analyse
Première action
Désinfecté
Seconde Action
Supprimé
Heuristique
Oui
Acceptez les avertissements
Oui
Extensions analysées
*;
Excludez les extensions
Analyse d'emails
Oui
Analyse des Archives
Oui
Analyser paquets programmes
Oui
Analyse des fichiers
Oui
Analyse de boot
Oui
Fichier analysé
Statut
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\085C0000.VBN=>(Quarantine-PE)
Infecté par: Trojan.Downloader.Conhook.BH
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\085C0000.VBN=>(Quarantine-PE)
Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AE00000.VBN=>(Quarantine-PE)
Infecté par: Trojan.Downloader.E.TR
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AE00000.VBN=>(Quarantine-PE)
Echec de la désinfection
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AE00000.VBN=>(Quarantine-PE)
Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AE00001.VBN=>(Quarantine-PE)
Infecté par: Trojan.Downloader.E.TR
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AE00001.VBN=>(Quarantine-PE)
Echec de la désinfection
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AE00001.VBN=>(Quarantine-PE)
Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AE00002.VBN=>(Quarantine-PE)
Infecté par: Trojan.Downloader.E.TR
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AE00002.VBN=>(Quarantine-PE)
Echec de la désinfection
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AE00002.VBN=>(Quarantine-PE)
Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AE00003.VBN=>(Quarantine-PE)
Infecté par: Trojan.Downloader.E.TR
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AE00003.VBN=>(Quarantine-PE)
Echec de la désinfection
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AE00003.VBN=>(Quarantine-PE)
Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0B300000.VBN=>(Quarantine-PE)
Infecté par: Win32.Virtob.BO
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0B300000.VBN=>(Quarantine-PE)
Echec de la désinfection
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0B300000.VBN=>(Quarantine-PE)
Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C0C0000.VBN=>(Quarantine-PE)=>(Embedded EXE o)
Infecté par: Trojan.Agent.DYH
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C0C0000.VBN=>(Quarantine-PE)=>(Embedded EXE o)
Echec de la désinfection
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C0C0000.VBN=>(Quarantine-PE)=>(Embedded EXE o)
Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C0C0000.VBN=>(Quarantine-PE)
Echec de la mise à jour
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C0C0000.VBN=>(Quarantine-PE)=>(Embedded EXE 3o)
Infecté par: Trojan.Agent.NGH
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C0C0000.VBN=>(Quarantine-PE)=>(Embedded EXE 3o)
Echec de la désinfection
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C0C0000.VBN=>(Quarantine-PE)=>(Embedded EXE 3o)
Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C0C0000.VBN=>(Quarantine-PE)
Echec de la mise à jour
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C0C0000.VBN=>(Quarantine-PE)=>(Embedded EXE 4o)
Infecté par: Trojan.Agent.AQV
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C0C0000.VBN=>(Quarantine-PE)=>(Embedded EXE 4o)
Echec de la désinfection
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C0C0000.VBN=>(Quarantine-PE)=>(Embedded EXE 4o)
Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C0C0000.VBN=>(Quarantine-PE)
Echec de la mise à jour
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C0C0001.VBN=>(Quarantine-PE)
Infecté par: Win32.Virtob.BQ
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C0C0001.VBN=>(Quarantine-PE)
Echec de la désinfection
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C0C0001.VBN=>(Quarantine-PE)
Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C0C0002.VBN=>(Quarantine-PE)
Infecté par: Win32.Virtob.BQ
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C0C0002.VBN=>(Quarantine-PE)
Echec de la désinfection
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C0C0002.VBN=>(Quarantine-PE)
Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C480000.VBN=>(Quarantine-PE)
Infecté par: Backdoor.Prorat.1.9.Dam.2
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C480000.VBN=>(Quarantine-PE)
Echec de la désinfection
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C480000.VBN=>(Quarantine-PE)
Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D200000.VBN=>(Quarantine-PE)
Infecté par: Trojan.Downloader.E.TR
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D200000.VBN=>(Quarantine-PE)
Echec de la désinfection
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D200000.VBN=>(Quarantine-PE)
Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D200001.VBN=>(Quarantine-PE)
Infecté par: Trojan.Downloader.E.TR
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D200001.VBN=>(Quarantine-PE)
Echec de la désinfection
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D200001.VBN=>(Quarantine-PE)
Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D200002.VBN=>(Quarantine-PE)
Infecté par: Trojan.Downloader.E.TR
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D200002.VBN=>(Quarantine-PE)
Echec de la désinfection
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D200002.VBN=>(Quarantine-PE)
Supprimé
C:\Documents and Settings\Marcel\Local Settings\Application Data\{8E94F725-8C1B-4DBD-B9F5-A623113F7B57}\Pando.msi=>(Embedded CAB)=>oovooinst.exe
Infecté par: Trojan.Generic.25641
C:\Documents and Settings\Marcel\Local Settings\Application Data\{8E94F725-8C1B-4DBD-B9F5-A623113F7B57}\Pando.msi=>(Embedded CAB)=>oovooinst.exe
Echec de la désinfection
C:\Documents and Settings\Marcel\Local Settings\Application Data\{8E94F725-8C1B-4DBD-B9F5-A623113F7B57}\Pando.msi=>(Embedded CAB)=>oovooinst.exe
Supprimé
C:\Documents and Settings\Marcel\Local Settings\Application Data\{8E94F725-8C1B-4DBD-B9F5-A623113F7B57}\Pando.msi=>(Embedded CAB)
Echec de la mise à jour
C:\Program Files\Pando Networks\Pando\oovooInst.exe
Infecté par: Trojan.Generic.25641
C:\Program Files\Pando Networks\Pando\oovooInst.exe
Echec de la désinfection
C:\Program Files\Pando Networks\Pando\oovooInst.exe
Supprimé
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP17\A0263770.dll
Infecté par: MemScan:Trojan.Agent.AFKM
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP17\A0263770.dll
Echec de la désinfection
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP17\A0263770.dll
Supprimé
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP2\A0252003.dll
Infecté par: DeepScan:Generic.NetAdware.74ACEAF4
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP2\A0252003.dll
Echec de la désinfection
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP2\A0252003.dll
Supprimé
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP2\A0252004.dll
Infecté par: Generic.NetAdware.461C2530
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP2\A0252004.dll
Echec de la désinfection
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP2\A0252004.dll
Supprimé
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP2\A0252055.dll
Infecté par: Generic.Otuboh.55B2DF89
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP2\A0252055.dll
Echec de la désinfection
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP2\A0252055.dll
Supprimé
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP2\A0252056.dll
Infecté par: Generic.Otuboh.55B2DF89
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP2\A0252056.dll
Echec de la désinfection
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP2\A0252056.dll
Supprimé
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282183.exe=>(RAR Sfx o)=>serial.exe
Infecté par: Trojan.Mezzia.CY
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282183.exe=>(RAR Sfx o)=>serial.exe
Echec de la désinfection
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282183.exe=>(RAR Sfx o)=>serial.exe
Supprimé
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282183.exe=>(RAR Sfx o)
Echec de la mise à jour
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282183.exe=>(RAR Sfx o)=>install.exe
Infecté par: Win32.Virtob.BQ
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282183.exe=>(RAR Sfx o)=>install.exe
Echec de la désinfection
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282183.exe=>(RAR Sfx o)=>install.exe
Supprimé
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282183.exe=>(RAR Sfx o)
Echec de la mise à jour
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282184.exe
Infecté par: DeepScan:Generic.Virtob.1.0D06FC6E
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282184.exe
Echec de la désinfection
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282184.exe
Supprimé
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282186.exe
Infecté par: DeepScan:Generic.Virtob.1.0D06FC6E
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282186.exe
Echec de la désinfection
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282186.exe
Supprimé
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282189.exe=>(RAR Sfx o)=>serial.exe
Infecté par: Trojan.Mezzia.CY
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282189.exe=>(RAR Sfx o)=>serial.exe
Echec de la désinfection
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282189.exe=>(RAR Sfx o)=>serial.exe
Supprimé
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282189.exe=>(RAR Sfx o)
Echec de la mise à jour
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282189.exe=>(RAR Sfx o)=>install.exe
Infecté par: Win32.Virtob.BQ
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282189.exe=>(RAR Sfx o)=>install.exe
Echec de la désinfection
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282189.exe=>(RAR Sfx o)=>install.exe
Supprimé
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP29\A0282189.exe=>(RAR Sfx o)
Echec de la mise à jour
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP30\A0283031.dll
Infecté par: Trojan.Vundo.DQV
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP30\A0283031.dll
Echec de la désinfection
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP30\A0283031.dll
Supprimé
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP34\A0283101.exe
Infecté par: Trojan.Fotomoto.F
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP34\A0283101.exe
Echec de la désinfection
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP34\A0283101.exe
Supprimé
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP50\A0291590.exe
Infecté par: Trojan.Generic.25641
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP50\A0291590.exe
Echec de la désinfection
C:\System Volume Information\_restore{70C219BC-5150-4D9F-83CC-3D65BD28289F}\RP50\A0291590.exe
Supprimé
C:\_OTMoveIt\MovedFiles\WINDOWS\system32\fccbyay.dll.vir
Infecté par: Trojan.Vundo.DQV
C:\_OTMoveIt\MovedFiles\WINDOWS\system32\fccbyay.dll.vir
Echec de la désinfection
C:\_OTMoveIt\MovedFiles\WINDOWS\system32\fccbyay.dll.vir
Supprimé
C:\_OTMoveIt\MovedFiles\WINDOWS\system32\jyrpvtbg.dll
Infecté par: Trojan.Vundo.DQO
C:\_OTMoveIt\MovedFiles\WINDOWS\system32\jyrpvtbg.dll
Echec de la désinfection
C:\_OTMoveIt\MovedFiles\WINDOWS\system32\jyrpvtbg.dll
Supprimé
C:\_OTMoveIt\MovedFiles\WINDOWS\system32\urqrstr.dll
Infecté par: Trojan.Vundo.DQV
C:\_OTMoveIt\MovedFiles\WINDOWS\system32\urqrstr.dll
Echec de la désinfection
C:\_OTMoveIt\MovedFiles\WINDOWS\system32\urqrstr.dll
Supprimé